ABB Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for ABB products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

4

In CISA KEV

2

Beyond CISA KEV

2

Sensor Observed

0

Virtual Patch Available

0

ABB KEVs Added by Year

Loading...

4 ABB KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2023-40748

PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php.

High Not in CISA 26 Jan 2026
CVE-2022-23134

Possible view of the setup pages by unauthenticated users if config file already exists

Confirmed In CISA 22 Feb 2022
CVE-2022-23131

Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML

Confirmed In CISA 22 Feb 2022
CVE-2024-6298

remote code execution

High Not in CISA 05 Jul 2024

Common Vulnerability Classes (CWE)

  • CWE-1287 — Improper Validation of Specified Type of Input 1
  • CWE-284 — Improper Access Control 1
  • CWE-290 — Authentication Bypass by Spoofing 1
  • CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology